CVE-2022-33873: Command Injection
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to execute arbitrary command in the underlying shell.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-33873?
CVE-2022-33873 is an OS Command Injection vulnerability in Console login components of FortiTester.
How does CVE-2022-33873 impact FortiTester?
CVE-2022-33873 allows an unauthenticated attacker to execute arbitrary commands in FortiTester.
What is the severity of CVE-2022-33873?
The severity of CVE-2022-33873 is critical with a CVSS score of 9.8.
Which versions of FortiTester are affected by CVE-2022-33873?
FortiTester versions 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, and 7.0.0 through 7.1.0 are affected by CVE-2022-33873.
How can I fix CVE-2022-33873 in FortiTester?
To fix CVE-2022-33873 in FortiTester, update to a version that is not affected.